1. Subscriptions
  2. Services
  3. Hardware
  4. Support

ClearFoundation

Forums
Welcome, Guest
Security Vulnerability: Webconfig Persistent XSS
(1 viewing) 1 Guest
Go to bottomPage: 1
TOPIC: Security Vulnerability: Webconfig Persistent XSS
#37124
Security Vulnerability: Webconfig Persistent XSS 3 Months, 3 Weeks ago  
I've found a persistent XSS vulnerability in the webconfig. Although the attack surface is limited it's still a practical attack against Webconfig Administrators. If someone could contact me regarding it that would be good. I've sent an email to security@clearfoundation.com about it but I didn't have much success the last time I reported something there but did have marginal success with the forum, so here I am.

Should be noted, those without the IDS are more exposed as the attack surface is larger.
J
Junior Boarder
Posts: 25
graphgraph
User Offline Click here to see the profile of this user
Last Edit: 2012/01/30 05:52 By JVFF.
The administrator has disabled public write access.
 
#37129
Re:Security Vulnerability: Webconfig Persistent XSS 3 Months, 3 Weeks ago  
J,

You sent the e-mail two hours ago. A good chunk of the Clear Team isn't even awake yet! You may want to give us a wee bit more time next time around.
Peter Baldwin
Developer
Posts: 1165
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#37131
Re:Security Vulnerability: Webconfig Persistent XSS 3 Months, 3 Weeks ago  
I didn't include the specific details in the post but I also wasn't completely generic like last time and I've found a better response time on the forum rather then email, also, there wasn't a problem the time before that (although that was an actual question).
J
Junior Boarder
Posts: 25
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
Go to topPage: 1
  get the latest posts directly to your desktop